XP Guardian 2010

Nice - did you need to run the .inf file ?

no the com worked. till it up dated.

Ok I ran mbam till clean. then avast 5. shutdown woke up this morn, ran avast found av.exe. moved to chest, ran again found some 2 trogin, moved to chest. then I deleted them ran avast one more time found 1 malware32 something. avast says its clean now. running a full with mbam right now. then going to reboot and run again. Do you think there mite be something these two programs don’t know about.

have not put the laptop on Internet after updated, as not to let it loose.

Possibly I would like to see a GMER run

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

Caution
These types of scans can produce false positives. Do NOT take any action on any “<— ROOKIT” entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
[*]Click NO
[*]In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
[*]Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity.
[]Click OK.
[
]GMER will produce a log. Click on the [Save…] button, and in the File name area, type in “GMER.txt
[*]Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

it was not a very long scan time.

i have had 2 clean scans from both avast and mbam after reboot. I felt safe enough to connect to internet.

heres the file

Looks good - all problems clear now ?

Thank you essexboy for the easy instructions, live win disk, mbam, the information, I will know were to start. Hope to give something back to you, and this forum.

I would like to become a member of UNITE. But I have a lot to learn

cheers

My pleasure - apart from Virut most computers can be recovered intact if you have the right tools

Do you repair computers for a living ?

Not main income, Started out Building my own pc’s got into Satellite Internet (Hughes). Then Web sites. Quiet Shine is my newest site not sure just what to do with it. Maybe protection tips or something. I have a few more. The first site I sold is Kim’s Kitchen. Good BBQ source. all html not very well coded but it works. I have improved since then. But from collecting parts from dead PC and Making a working PC and selling, I get a few infected and broke repairs. Hobby I guess, self learned. I make a little money.

Viruses or malware. That gets me. I mean people just browsing the web and then there pc taken hostage for ransom. They have to pay to get rid of it, pay to hopefully stay protected. Or learn how to their self. Someone like you is a blessing to have met. I find it worth the effort to learn, and interesting.

     "Virut" Have to look that up.

Thanks again for the help essexboy, thanks Pondus .

have a read of miekiemoes blog here.

Very interesting. But leads to so many questions. I had dun a search earlier, and obviously came up with a lot of different removal tools. A definition on Virut, and some others. These questions can be rhetorical. Because I think the answers could be different in different cases. But,
is it limited to .EXE and .SCR files? I saw the html iframe way to spread.

Does the writer attach home users? I don’t have any finances to profit from. That just mean and destructive.

I have 4 drives. 2 for storage, xp, 7. Will it hide? Man to lose all 4 of my drives.

can it be detected real time? So you would know not to backup after that point.

Why would someone need a virus like that, Kicks? What if the virus activated on the writers pc and he lost all his data, that was a dumb question.

Same precautions be taken to protect from infection or is it total hopeless to protect from infection? Sounds hopeless if infected.

The idea behind virut is to make a spambot that hides within the system - but the code writers are not quite up to scratch. At a penny for 10 spam e-mails it will add up

It can be caught before it runs, I have had some cases where it was stopped dead in its tracks and there was no harm to the computer, but once it has infected one file then it is game over

These are the known infection vectors

DO NOT backup any applications or installers and DO NOT backup any files with the following extensions:
[].exe
[
].scr
[].htm
[
].html
[].xml
[
].zip
[].rar
[
].doc
[].jpg
[
].pdf

If a file is not run then it will not get infected, but once run it is open season. Virut is mainly spread by infected P2P downloads, cracks and keygens, keep away from those and you survival chances increase greatly

@ tbint

If you are serious about learning to become a malware fighter

The following are websites who host training facilities. The mission of these facilities is to teach normal people how to become malware fighters (in random order).
http://forums.malwarebytes.org/index.php?s=&showtopic=40872&view=findpost&p=203443

United Network of Instructors and Trained Eliminators
http://www.uniteagainstmalware.com/schools.php

Thanks again for the help essexboy, thanks Pondus .
Your wellcome.... ;)

Moore virut info

Virus:W32/Virut http://www.f-secure.com/v-descs/virus_w32_virut.shtml
http://en.wikipedia.org/wiki/Polymorphic_code
http://blog.avast.com/2009/07/14/buggy-file-infectors/
http://blog.avast.com/2010/01/08/file-infectors-part-2/

Being totally biased I would recommend GeeksToGo as I am teaching there ;D